Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add warning about publicly exposing usernames. #44

Open
SijmenHuizenga opened this issue Feb 22, 2019 · 1 comment
Open

Add warning about publicly exposing usernames. #44

SijmenHuizenga opened this issue Feb 22, 2019 · 1 comment
Assignees

Comments

@SijmenHuizenga
Copy link

Hi! Awesome work with this plugin, we use it all the time and it works superbe!

I have just one suggestion: add a notice to the top of the readme, wiki and atlassian-plugin-page that warns administrators that by default, usernames will be exposed to the public. Maybe something along the lines of:

Be aware, this plugin publicly exposes some sensitive data by default. The metrics page exposes the username of who last logged in, who last edited issues in every project and some more usernames. You should enable token protection to make sure the public cannot view usernames.

@AndreyVMarkelov
Copy link
Owner

Will do

@AndreyVMarkelov AndreyVMarkelov self-assigned this May 4, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants